lead-qualification
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted lead parameters (name, company, email) and instructs the agent to perform external searches and web fetches against these targets.
- Ingestion points: Input parameters (
<name> <email or company>) and pasted lists of leads insideSKILL.mdsteps 1 and 2. - Boundary markers: Absent. There are no delimiters or instruction-isolation markers enforced on the parsed lead tokens or fetched webpage text.
- Capability inventory: The skill leverages the
Bashtool as defined in the allowed-tools configuration, which represents an executable system capability tier. - Sanitization: No sanitization, escaping, or strict text filtering is specified before evaluating fetched data from external sites.
- [COMMAND_EXECUTION]: The skill specifies the
Bashtool within itsallowed-toolsfrontmatter section. While no dangerous scripts or explicit shell payloads are present in the static markdown instructions, assigning shell execution privileges creates a surface that must be coupled with human review checkpoints if external untrusted context is parsed.
Audit Metadata